深色模式
日志合规留存
金融、医疗等行业对日志留存有法定最短期限(常见 6 个月到数年),且要求防篡改、可审计。本文讲如何设定留存策略与合规保护措施,通用不针对特定法规。
适用环境
bash
# 查看当前索引保留设置
curl -s 'http://localhost:9200/_ilm/policy?pretty' | head
# 查看 Loki 保留配置
curl -s http://localhost:3100/config | grep -i compactor1
2
3
4
2
3
4
操作步骤
1. ElasticSearch:用 ILM 设合规保留期
bash
curl -X PUT "http://localhost:9200/_ilm/policy/compliance-keep" -H 'Content-Type: application/json' -d '{
"policy": {
"phases": {
"hot": { "min_age":"0ms", "actions": { "rollover": { "max_age":"30d" } } },
"cold": { "min_age":"90d", "actions": { "migrate":{"data_tier":"cold"} } },
"delete":{ "min_age":"365d", "actions": { "delete": {} } }
}
}
}'1
2
3
4
5
6
7
8
9
2
3
4
5
6
7
8
9
2. Loki:用 compactor 配置保留
yaml
# loki.yaml
compactor:
retention_enabled: true
delete_request_store: s3
limits_config:
retention_period: 365d1
2
3
4
5
6
2
3
4
5
6
3. 防篡改:开启写后不可改(WORM)
bash
# ES:索引设为 read-only 归档
curl -X PUT "http://localhost:9200/logs-archive-*/_settings" -H 'Content-Type: application/json' -d '{"index.blocks.write": true}'1
2
2
DANGER
合规留存的日志要定期做完整性校验(哈希归档),并离线备份。单纯依赖 ILM 删除策略可能误删审计所需数据,删除前需审批。
验证
bash
curl -s http://localhost:9200/_ilm/policy/compliance-keep?pretty | grep min_age
curl -s http://localhost:3100/config | grep retention_period1
2
2
常见坑
WARNING
保留策略与脱敏要配合:合规要求留存,但 PII 又要脱敏。建议留存前完成脱敏,或在合规库中单独控制访问权限。